> Source: [sk164242](https://support.checkpoint.com/results/sk/sk164242)

# sk164242 - User and Device Management  R80.20

| Property | Value |
|----------|-------|
| Solution ID | sk164242 |
| Date Created | 2019-12-24 |
| Last Modified | 2022-09-07 |
| Technical Level | General |

## Solution

UDM Product Description
-----------------------

User and Device Management (UDM) is a web based application that manages a range of user and device related tasks in an organization. A typical user accesses organizational resources from multiple devices: computers, laptops, smartphones, and tablets.

UDM provides a unified environment for managing various user and device related tasks, such as provisioning, transparency of access via SmartLog logs, viewing user and device details, certificate management, AD user management, and FDE password recovery (for Endpoint Security clients).  

With UDM, security administrators can delegate user and device management tasks to Help Desk administrators. This delegation of responsibilities lets the network security team handle security policy issues and the Help Desk team manage some user access tasks.  

**NOTE:**

To migrate from R77.30 version please ensure that the latest Jumbo hot fix for R77.30 was installed (certain fields were changed) prior to the migration operation.  
[User and Device Management R77.30.01 (Hotfix #9)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166635&partition=Basic&product=User "SK link")

What's New
----------

* Support installation on R80.20.

For UDM installation on R77.30 please go to [sk166635](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166635).  

UDM Configuration
-----------------

R80.20 UDM HF9 is installed on a separate machine (optionally on a VMware VM) and connects to different Security Management Servers or Multi-Domain Security Management Servers.

### Licensing

UDM HF9 Server doesn't require a Security Management license if connecting to different Security Management Servers or Multi-Domain Security Management Servers.

For further assistance, [contact Check Point Account Services](http://www.checkpoint.com/support-services/contact-support/index.html):

* by using [Live Chat](https://supportcenter.checkpoint.com/supportcenter/ChatRedirect.jsp)
* by completing an [Online Form](http://www.checkpoint.com/form/contact_account.html)
* by phone: Americas: +1-972-444-6600 option 5, or International: +972-3-611-5100 option 5

### Installation options

#### Clean Installation

1. Install [Security Management Server R80.20 GA](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122485). (It was also tested successfully on Jumbo Hotfix Accumulator for R80.20 Take 118)
2. Update to latest CPUSE deployment agent ([sk92449 - Check Point Upgrade Service Engine (CPUSE) - Gaia Deployment Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449)).
3. Download the HF9 [installation file](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=102564).
4. Connect to the management server Gaia Portal. (Default address is: https://\<ip_address\>/)
5. Navigate to Upgrades (CPUSE) pane. Click on "Status and Actions".
6. On the toolbar, select "Import Package" - browse for the CPUSE Offline package (TGZ file) - click on "Import".
7. Select the hotfix package - click on "Install Update" button on the toolbar.  
   Note: Machine will automatically reboot after installation process is completed.
8. Connect to the Management server via SSH and run udm_activation.  
   Note: After the process will finish, you will be able to connect to Gaia Portal through https://\<ip_address\>:4434/.
9. Setup UDM using [R77.30.01 HF1 User and Device Management Administration Guide](http://supportcontent.checkpoint.com/documentation_download?ID=47003)
10. Follow [sk114934](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114934&partition=Advanced&product=User) and [sk116412](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116412&partition=Advanced&product=User) .

#### Upgrade From R77.30.01 UDM HF1 or later:

1. Backup $UDMDIR/conf content from your currnet UDM machine.
2. Make sure to backup your SandBlast Mobile server details.
3. Commit the above clean installation procedure.
4. Copy $UDMDIR/conf content from the old UDM machine to the new one.
5. Restart the UDM service:  
   udmstop; udmstart
6. Reconfigure all the settings in UDM portal.

Download {#Downloads}
---------------------

|----------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Package                          | Link                                                                                                                                                                                                                                                                                                                                                                                                            |
| R80.20 UDM Hotfix #9 for Gaia OS | [](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=101751)[![](https://sc1.checkpoint.com/sc/images/download-m.png "R77.30.01 UDM Hotfix #9 for Gaia OS")](https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=102564 "R80.20 UDM Hotfix #9 for Gaia OS") (TGZ) |

Known Limitations
-----------------

**Important notes:**

* To get a fix for an issue listed below contact [Check Point Support](http://www.checkpoint.com/services/contact/index.html) with the issue ID.
* To see if an issue has been fixed in other releases, search for the issue ID in Support Center.

|----------|--------------------------------------------------------------------------------------------------------------|
| ID       | Symptoms                                                                                                     |
| Installation                                                                                                           ||
| 01892463 | The UDM portal cannot be enabled on a standalone installation.                                               |
| SMTP                                                                                                                   ||
| 01912002 | The UDM portal does not support SMTP with TLS authentication                                                 |
| Mobile Threat Prevention Integration                                                                                   ||
| 01933444 | In the Mobile Threat Prevention tab of the portal, the user does not see the message when a session expires. |
| 02349950 | No support for non-English characters for devices created via MTP manual enrolment in UDM.                   |
| Active Directory                                                                                                       ||
| 01908742 | The UDM portal does not support LDAP groups that contain AD special characters.                              |
| Management Compatibility                                                                                               ||
|          | The UDM does not support RSA authentication.                                                                 |
|          | This version can be connected to management with version R80.20 and above.                                   |
|          | Access to the UDM portal is done via IP only, using domain name will not work.                               |
|          | The UDM does not support authentication via Radius server                                                    |

Revision History {#Revision History}
------------------------------------

Show / Hide the revision history   

|-------------|---------------------------------|
| Date        | Description                     |
| 04 May 2020 | Public release of this article. |
| 31 Dec 2019 | First release of this article.  |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
